🇱🇻
garmtech.com
2026-09-08 10:52:51
(8 hours ago)
Attempted access to sensitive endpoint (/.env.prod) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/.env.prod) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:57:30
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.155.95 (95.155.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.155.95 (95.155.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:57:22.343704 2026] [security2:error] [pid 20812:tid 20812] [client 35.229.155.95:36996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.yohel.org"] [uri "/.env.local"] [unique_id "ap-jwsVTYOGIwDXr85trQAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:39:08
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.155.95 (95.155.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.155.95 (95.155.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:39:02.929796 2026] [security2:error] [pid 22629:tid 22629] [client 35.229.155.95:52448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.justkoolit.com"] [uri "/.htaccess"] [unique_id "ap-fdm1syPkUU5xNWP_WyQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 03:49:37
(15 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇯🇵
ZEROVOX
2026-09-07 07:00:14
(1 day ago)
CrowdSec: crowdsecurity/http-probing detected
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-06 21:59:58
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇺🇸
thieuleu
2026-09-06 06:23:05
(2 days ago)
Unauthorized connection attempt blocked by firewall policy. Web application hardening active.
Brute-Force
Exploited Host
🇺🇸
TPI-Abuse
2026-09-06 03:50:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.155.95 (95.155.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.155.95 (95.155.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:50:39.886800 2026] [security2:error] [pid 28089:tid 28089] [client 35.229.155.95:53550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.teamworksales.com"] [uri "/.env.backup"] [unique_id "apzjDxNDPxJgWvJ5NqT9wwAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:00:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.155.95 (95.155.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.155.95 (95.155.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:59:52.089223 2026] [security2:error] [pid 27058:tid 27058] [client 35.229.155.95:35306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.infolinkqr.com"] [uri "/.env"] [unique_id "apzXKOcjJ-ICirG-3bOHmgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:43:38
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.229.155.95 (95.155.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.155.95 (95.155.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:43:33.463244 2026] [security2:error] [pid 4693:tid 4693] [client 35.229.155.95:41980] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||exhaustthelimits.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "exhaustthelimits.org"] [uri "/dump.sql"] [unique_id "apzTVcJj079xiVrz_Q5hqQAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
SysAdmin Dylan
2026-09-06 02:30:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.155.95 (TW/Taiwan/95.155.229.35.bc.googl ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.155.95 (TW/Taiwan/95.155.229.35.bc.googleusercontent.com): 10 in the last 3600 secs
show less
Brute-Force
🇺🇸
xxkodedxx
2026-09-06 01:39:21
(2 days ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get, 2× edge-block ...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get, 2× edge-block in 10m window.
Origin: TW / AS396982 Google LLC
Active: 01:39:11→01:39:12 UTC
Volume: 5 HTTP req, 17 honeypot probe(s)
Bait taken: /wp-config.php~, /.env.save, /wp-config.php.swp, /wp-config.php.bak, /actuator/env
Status mix: 301×3 444×2
UA: "crusader-worker/1.0"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 01:29:28
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇩🇪
FD-IX
2026-09-06 01:01:29
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:51:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.155.95 (95.155.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.155.95 (95.155.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:51:37.420006 2026] [security2:error] [pid 2276:tid 2276] [client 35.229.155.95:45226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "entertainmentcapitol.com"] [uri "/.env.prod"] [unique_id "apy5GUvBPDzDqxNs2U2shgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack